Skip to content

About

Forge crypt(3) password hashes for every format /etc/shadow accepts (DES, MD5, SHA-256, SHA-512, Blowfish) — a lab/CTF tool

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

shadowsmith

CI License: MIT Python 3.8+

Forge a password hash in every crypt(3) format that /etc/shadow accepts — DES, MD5, SHA-256, SHA-512, and Blowfish — using the same libc algorithms your system uses to verify logins.

Built for lab and CTF environments (INE eJPT, HTB, TryHackMe, etc.) where you've landed write access to /etc/shadow and need a correctly formatted hash to drop in for privilege escalation practice.

Example

$ shadowsmith hunter2

Generating shadow-compatible hashes for password: 'hunter2'

Format                              Hash
----------------------------------------------------------------------------------------------------
DES (no prefix, legacy, 13 chars)   yw0gkhHNVIuN6
MD5 ($1$)                           $1$aknz6teF$lqEfSf2uFEd1Af2MsZJli/
SHA-256 ($5$)                       $5$fXyxyIUxDevI7ZRj$dArZtkUixY/9JbZfi04/37hN83Nfm1t.6tS9dqJSwF5
SHA-512 ($6$)                       $6$PCdL.fIbv44SXrNF$y97tVVJVjrc.UV4yZ.38KDVfN05ueKCVIV3Y4dNRnE3Ws10DKxGkF5xS4/gmnFNbvSxL5gGL.69AJMvMe2wWG/
Blowfish ($2b$, if supported)       $2b$12$B0NUIAmyRHYNBoq.0FkGheUSPcxFymo76XPgfEO.hlT48dgzvGhXu

To use one of these in /etc/shadow, replace the second field:
    username:<hash-from-above>:<lastchange>:<min>:<max>:<warn>:::

Double-check the field count (colons) matches the original line exactly.

Installation

pip / pipx

pipx install git+https://github.com/seggewiss/shadowsmith.git
shadowsmith hunter2

Or just run it directly with no install:

python3 generator.py hunter2

Docker

docker build -t shadowsmith .
docker run --rm shadowsmith hunter2

devenv (Nix)

If you use devenv:

devenv shell
shadowsmith hunter2

Supported formats

Format Prefix Notes
DES (none) Legacy 13-char hash, 8-char password limit
MD5 $1$
SHA-256 $5$
SHA-512 $6$ Default on most modern Linux distros
Blowfish $2b$ Only on platforms whose libc supports it (e.g. musl/libxcrypt); shows as unsupported on glibc

Availability of each format depends on what your platform's libc exposes to Python's crypt module — unsupported formats are reported as such instead of erroring out.

A note on Python 3.13+

The crypt module was removed from the standard library in Python 3.13 (PEP 594). If you're on 3.13+, install the backport:

pip install legacycrypt

The Docker image pins Python 3.12 so this isn't a concern there.

Disclaimer

For use in environments you're authorized to test — labs, CTFs, and your own systems. Don't use this against systems you don't have permission to access.

License

MIT

About

Forge crypt(3) password hashes for every format /etc/shadow accepts (DES, MD5, SHA-256, SHA-512, Blowfish) — a lab/CTF tool

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages